Vulnerability Details CVE-2020-8908
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.5%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 2.1
Products affected by CVE-2020-8908
-
cpe:2.3:a:google:guava:1.0
-
cpe:2.3:a:google:guava:10.0
-
cpe:2.3:a:google:guava:10.0.1
-
cpe:2.3:a:google:guava:11.0
-
cpe:2.3:a:google:guava:11.0.1
-
cpe:2.3:a:google:guava:11.0.2
-
cpe:2.3:a:google:guava:12.0
-
cpe:2.3:a:google:guava:12.0.1
-
cpe:2.3:a:google:guava:13.0
-
cpe:2.3:a:google:guava:13.0.1
-
cpe:2.3:a:google:guava:14.0
-
cpe:2.3:a:google:guava:14.0.1
-
cpe:2.3:a:google:guava:15.0
-
cpe:2.3:a:google:guava:16.0
-
cpe:2.3:a:google:guava:16.0.1
-
cpe:2.3:a:google:guava:17.0
-
cpe:2.3:a:google:guava:18.0
-
cpe:2.3:a:google:guava:19.0
-
cpe:2.3:a:google:guava:2.0
-
cpe:2.3:a:google:guava:20.0
-
cpe:2.3:a:google:guava:21.0
-
cpe:2.3:a:google:guava:22.0
-
cpe:2.3:a:google:guava:23.0
-
cpe:2.3:a:google:guava:23.1
-
cpe:2.3:a:google:guava:23.2
-
cpe:2.3:a:google:guava:23.3
-
cpe:2.3:a:google:guava:23.4
-
cpe:2.3:a:google:guava:23.5
-
cpe:2.3:a:google:guava:23.6
-
cpe:2.3:a:google:guava:23.6.1
-
cpe:2.3:a:google:guava:24.0
-
cpe:2.3:a:google:guava:24.1
-
cpe:2.3:a:google:guava:24.1.1
-
cpe:2.3:a:google:guava:25.0
-
cpe:2.3:a:google:guava:25.1
-
cpe:2.3:a:google:guava:26.0
-
cpe:2.3:a:google:guava:27.0
-
cpe:2.3:a:google:guava:27.0.1
-
cpe:2.3:a:google:guava:27.1
-
cpe:2.3:a:google:guava:28.0
-
cpe:2.3:a:google:guava:28.1
-
cpe:2.3:a:google:guava:28.2
-
cpe:2.3:a:google:guava:29.0
-
cpe:2.3:a:google:guava:3.0
-
cpe:2.3:a:google:guava:30.0
-
cpe:2.3:a:google:guava:30.1
-
cpe:2.3:a:google:guava:4.0
-
cpe:2.3:a:google:guava:5.0
-
cpe:2.3:a:google:guava:6.0
-
cpe:2.3:a:google:guava:7.0
-
cpe:2.3:a:google:guava:8.0
-
cpe:2.3:a:google:guava:9.0
-
cpe:2.3:a:netapp:active_iq_unified_manager:-
-
cpe:2.3:a:oracle:commerce_guided_search:11.3.2
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.14.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1
-
cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.4.0
-
cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.5.0
-
cpe:2.3:a:oracle:data_integrator:12.2.1.3.0
-
cpe:2.3:a:oracle:data_integrator:12.2.1.4.0
-
cpe:2.3:a:oracle:nosql_database:19.3.12
-
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57
-
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58
-
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59
-
cpe:2.3:a:oracle:primavera_unifier:17.10
-
cpe:2.3:a:oracle:primavera_unifier:17.11
-
cpe:2.3:a:oracle:primavera_unifier:17.12
-
cpe:2.3:a:oracle:primavera_unifier:17.7
-
cpe:2.3:a:oracle:primavera_unifier:17.8
-
cpe:2.3:a:oracle:primavera_unifier:17.9
-
cpe:2.3:a:oracle:primavera_unifier:18.8
-
cpe:2.3:a:oracle:primavera_unifier:19.12
-
cpe:2.3:a:oracle:primavera_unifier:20.12
-
cpe:2.3:a:oracle:primavera_unifier:21.12
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0.1
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0.2
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0.1
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.1
-
cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0
-
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0
-
cpe:2.3:a:quarkus:quarkus:0.0.1
-
cpe:2.3:a:quarkus:quarkus:0.1.0
-
cpe:2.3:a:quarkus:quarkus:0.10.0
-
cpe:2.3:a:quarkus:quarkus:0.11.0
-
cpe:2.3:a:quarkus:quarkus:0.12.0
-
cpe:2.3:a:quarkus:quarkus:0.13.0
-
cpe:2.3:a:quarkus:quarkus:0.13.1
-
cpe:2.3:a:quarkus:quarkus:0.13.2
-
cpe:2.3:a:quarkus:quarkus:0.13.3
-
cpe:2.3:a:quarkus:quarkus:0.14.0
-
cpe:2.3:a:quarkus:quarkus:0.15.0
-
cpe:2.3:a:quarkus:quarkus:0.16.0
-
cpe:2.3:a:quarkus:quarkus:0.16.1
-
cpe:2.3:a:quarkus:quarkus:0.17.0
-
cpe:2.3:a:quarkus:quarkus:0.18.0
-
cpe:2.3:a:quarkus:quarkus:0.19.0
-
cpe:2.3:a:quarkus:quarkus:0.19.1
-
cpe:2.3:a:quarkus:quarkus:0.2.0
-
cpe:2.3:a:quarkus:quarkus:0.20.0
-
cpe:2.3:a:quarkus:quarkus:0.21.0
-
cpe:2.3:a:quarkus:quarkus:0.21.1
-
cpe:2.3:a:quarkus:quarkus:0.21.2
-
cpe:2.3:a:quarkus:quarkus:0.22.0
-
cpe:2.3:a:quarkus:quarkus:0.23.0
-
cpe:2.3:a:quarkus:quarkus:0.23.1
-
cpe:2.3:a:quarkus:quarkus:0.23.2
-
cpe:2.3:a:quarkus:quarkus:0.24.0
-
cpe:2.3:a:quarkus:quarkus:0.25.0
-
cpe:2.3:a:quarkus:quarkus:0.26.0
-
cpe:2.3:a:quarkus:quarkus:0.26.1
-
cpe:2.3:a:quarkus:quarkus:0.27.0
-
cpe:2.3:a:quarkus:quarkus:0.28.0
-
cpe:2.3:a:quarkus:quarkus:0.28.1
-
cpe:2.3:a:quarkus:quarkus:0.3.0
-
cpe:2.3:a:quarkus:quarkus:0.4.0
-
cpe:2.3:a:quarkus:quarkus:0.5.0
-
cpe:2.3:a:quarkus:quarkus:0.6.0
-
cpe:2.3:a:quarkus:quarkus:0.7.0
-
cpe:2.3:a:quarkus:quarkus:0.8.0
-
cpe:2.3:a:quarkus:quarkus:0.9.0
-
cpe:2.3:a:quarkus:quarkus:0.9.1
-
cpe:2.3:a:quarkus:quarkus:1.0.0
-
cpe:2.3:a:quarkus:quarkus:1.0.1
-
cpe:2.3:a:quarkus:quarkus:1.1.0
-
cpe:2.3:a:quarkus:quarkus:1.1.1
-
cpe:2.3:a:quarkus:quarkus:1.10.0
-
cpe:2.3:a:quarkus:quarkus:1.10.1
-
cpe:2.3:a:quarkus:quarkus:1.10.2
-
cpe:2.3:a:quarkus:quarkus:1.10.3
-
cpe:2.3:a:quarkus:quarkus:1.10.4
-
cpe:2.3:a:quarkus:quarkus:1.10.5
-
cpe:2.3:a:quarkus:quarkus:1.11.0
-
cpe:2.3:a:quarkus:quarkus:1.11.1
-
cpe:2.3:a:quarkus:quarkus:1.11.2
-
cpe:2.3:a:quarkus:quarkus:1.11.3
-
cpe:2.3:a:quarkus:quarkus:1.2.0
-
cpe:2.3:a:quarkus:quarkus:1.2.1
-
cpe:2.3:a:quarkus:quarkus:1.3.0
-
cpe:2.3:a:quarkus:quarkus:1.3.1
-
cpe:2.3:a:quarkus:quarkus:1.3.2
-
cpe:2.3:a:quarkus:quarkus:1.3.3
-
cpe:2.3:a:quarkus:quarkus:1.3.4
-
cpe:2.3:a:quarkus:quarkus:1.4.0
-
cpe:2.3:a:quarkus:quarkus:1.4.1
-
cpe:2.3:a:quarkus:quarkus:1.4.2
-
cpe:2.3:a:quarkus:quarkus:1.5.0
-
cpe:2.3:a:quarkus:quarkus:1.5.1
-
cpe:2.3:a:quarkus:quarkus:1.5.2
-
cpe:2.3:a:quarkus:quarkus:1.6.0
-
cpe:2.3:a:quarkus:quarkus:1.6.1
-
cpe:2.3:a:quarkus:quarkus:1.7.0
-
cpe:2.3:a:quarkus:quarkus:1.7.1
-
cpe:2.3:a:quarkus:quarkus:1.7.2
-
cpe:2.3:a:quarkus:quarkus:1.7.3
-
cpe:2.3:a:quarkus:quarkus:1.7.4
-
cpe:2.3:a:quarkus:quarkus:1.7.5
-
cpe:2.3:a:quarkus:quarkus:1.7.6
-
cpe:2.3:a:quarkus:quarkus:1.8.0
-
cpe:2.3:a:quarkus:quarkus:1.8.1
-
cpe:2.3:a:quarkus:quarkus:1.8.2
-
cpe:2.3:a:quarkus:quarkus:1.8.3
-
cpe:2.3:a:quarkus:quarkus:1.9.0
-
cpe:2.3:a:quarkus:quarkus:1.9.1
-
cpe:2.3:a:quarkus:quarkus:1.9.2